3 ms·
You do not necessarily need to hire a DPO. Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
by snogaraleal 8y ago
You do not necessarily need to hire a DPO.
Read the law or, at least, read the official FAQ. Your evaluation of the impact of the law on your project is lazy.
- drcode 8y agoReading the FAQ, the only way to really safely ignore the DPO provision would be to hire a law firm with GDPR expertise to parse the vague language in the law and to give written guidance as to whether the law applies to each specific web site, which you can then present to EU authorities in the future to show you performed due diligence to try to meet the requirements of the law.
- jimnotgym 8y agoI can only think you are not familiar with European principle based law vs US rule based law. Where you see 'vague', I see 'flexible' and 'able to move with the times'
- yesco 8y agoHave you considered that a law being "flexible" and "able to move with the times" is exactly why someone wouldn't like it being vague? A law that is "flexible" means that it's a law that can be arbitrarily applied. A law that can "move with the times" means that what might be fine now won't be fine later and just maybe you will be the first to find out. It doesn't matter if European law has a history of being "principle based", if it can fuck you then someday it just might. Europeans might be fine with this, but I think most Americans would not be. If I was in OP's position I would do the same thing, by simply blocking an IP range all possibility of being made an example of by some people from another continent is flushed down the drain. I'm absolutely baffled why people think this is absurd, if you're not even making any income off of it, why would you ever open yourself up to such expensive potential liability?
- jimnotgym 8y agoI think comments like that just open you up to rather obvious jibes about how long European law has been around vs the US. I will leave the reader to make their own jokes.
- snogaraleal 8y agoThe FAQ is referencing the legal concepts in the law's text. For example "sensitive data": "(...) including for the processing of special categories of personal data (‘sensitive data’)", special categories are mentioned on Article 9. "(...) personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation" Do you store or transfer or process any of that data on a large scale? Is it personally identifiable? "Processing" is defined on Article 4. I believe the original legal text, though not the easiest to read, gives you a fairly clear idea on where your organization or project should stand with respect to GDPR. (1) What data do you process? (2) How is it connected to your economic activity? (3) How do users consent this use of the data? (4) Is your data "sensitive data"? If you're some random guy online doing large scale processing of "sensitive data" you better hire a law firm with GDPR expertise to understand and comply with the law, I mean, that's the whole point.
- tobltobs 8y agoFrom Article 37 GDPR: (1) The controller and the processor shall designate a data protection officer in any case where: ... (c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or .... Article 9 describes personal data as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, ... I would say that messages send via IM are personal data like described in Article 9. I also would check the "large scale" checkbox. So in my interpretation he will need a DPO.
- snogaraleal 8y agoI don't think he has access to the messages, it's an IM client. If he did have access to the messages then I fail to see how having to hire a DPO in that case would be outrageous. If anything, that's the reasonable thing to do.
- tobltobs 8y agoAvoiding the cost and removing the app from the EU market is also a reasonable decision.
- stordoff 8y ago> Even though no message traffic passes through Monal’s sever He has no data of the kind described in Article 9.
- zmmmmm 8y ago> Your evaluation of the impact of the law on your project is lazy That seems a very pejorative way to describe it. You can say the same thing in terms of "you could probably keep operating if you put a lot of effort into understanding the details of the law" which kind of proves the author's point: this creates work for people and why should someone do that work for no return? Where does the presumption that people owe EU citizens these services at a higher standard than the rest of the world is content (legally) to accept?